Court Rules

Privacy Enforcement Tracker

1,672 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.

1,672

Total Actions

16

Jurisdictions

$50.5B+

Total Fines Tracked

Access this data programmatically:MCP Server API Docs
HHSEnforcement Action

McKenzie Memorial Hospital

McKenzie Memorial Hospital (Healthcare Provider, MI) reported a HIPAA breach affecting 58,839 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Gastroenterology Consultants of South Texas

Gastroenterology Consultants of South Texas (Healthcare Provider, TX) reported a HIPAA breach affecting 44,579 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Blue Shield of California

Blue Shield of California (Health Plan, CA) reported a HIPAA breach affecting 783 individuals. Breach type: Unauthorized Access/Disclosure. Location of breached information: Laptop, Network Server, Other.

LowData BreachHealth DataUnauthorized Data Sharing
HHSEnforcement Action

Kettering Adventist Healthcare

Kettering Adventist Healthcare (Healthcare Provider, OH) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
TXSettlement

Meta Platforms, Inc.(Meta)

Texas Attorney General Ken Paxton secured a record-setting $1.4 billion settlement with Meta for unlawfully capturing and using the biometric data of millions of Texans, marking one of the largest privacy settlements in U.S. history.

HighBiometric Data

$1.4B

HHSEnforcement Action

Dr. Michael Bilikas and Associates d.b.a. 32 Pearls

Dr. Michael Bilikas and Associates d.b.a. 32 Pearls (Healthcare Provider, WA) reported a HIPAA breach affecting 23,517 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
TXEnforcement Action

Meta, Google, General Motors, TikTok, and other companies(Meta)

Texas Attorney General Ken Paxton announced a comprehensive privacy enforcement initiative, achieving record settlements with Meta ($1.4B) and Google ($1.375B) for biometric and geolocation data violations, suing General Motors and TikTok, and investigating numerous companies for children's data and AI practices. The AG's office has enforced multiple Texas privacy laws and registered over 200 data brokers.

CriticalBiometric DataGeolocation DataChildren's Data

$2.8B

HHSEnforcement Action

OrthoAtlanta LLC

OrthoAtlanta LLC (Business Associate, GA) reported a HIPAA breach affecting 626 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Infinite Services, Inc.

Infinite Services, Inc. (Healthcare Provider, NY) reported a HIPAA breach affecting 31,742 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Equilibria Mental Health Services

Equilibria Mental Health Services (Healthcare Provider, PA) reported a HIPAA breach affecting 3,232 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Keys Pathology Associates, PA

Keys Pathology Associates, PA (Healthcare Provider, FL) reported a HIPAA breach affecting 20,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

The Brien Center for Mental Health and Substance Abuse Services

The Brien Center for Mental Health and Substance Abuse Services (Healthcare Provider, MA) reported a HIPAA breach affecting 5,427 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Human Development Services of Westchester

Human Development Services of Westchester (Healthcare Provider, NY) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Oregon Specialty Group

Oregon Specialty Group (Healthcare Provider, OR) reported a HIPAA breach affecting 3,337 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Self Regional Healthcare

Self Regional Healthcare (Healthcare Provider, SC) reported a HIPAA breach affecting 26,696 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
CTSettlement

Capulet Entertainment

Connecticut Attorney General settled with Capulet Entertainment over the failed Capulet Fest 2024, which was abruptly relocated and partially cancelled, leaving ticketholders without refunds. The settlement provides up to $50,000 in consumer refunds and imposes future requirements including performance bonds and contractor commitments.

Low
HHSEnforcement Action

Mid South Rehab Services Inc.

Mid South Rehab Services Inc. (Healthcare Provider, MS) reported a HIPAA breach affecting 1,316 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Williamsburg Area Medical Assistance Corporation d/b/a Olde Towne Medical and Dental Center (OTMDC)

Williamsburg Area Medical Assistance Corporation d/b/a Olde Towne Medical and Dental Center (OTMDC) (Healthcare Provider, VA) reported a HIPAA breach affecting 2,567 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Regency Oaks

Regency Oaks (Healthcare Provider, FL) reported a HIPAA breach affecting 2,008 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Freedom Square of Seminole

Freedom Square of Seminole (Healthcare Provider, FL) reported a HIPAA breach affecting 3,473 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Picis Clinical Solutions, Inc. d/b/a Medstreaming

Picis Clinical Solutions, Inc. d/b/a Medstreaming (Business Associate, MA) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Anne Arundel Dermatology

Anne Arundel Dermatology (Healthcare Provider, MD) reported a HIPAA breach affecting 1,905,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

CriticalData BreachHealth DataSecurity Failure
HHSEnforcement Action

Freedom Plaza Senior Living

Freedom Plaza Senior Living (Healthcare Provider, FL) reported a HIPAA breach affecting 4,847 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Covenant Health

Covenant Health (Business Associate, MA) reported a HIPAA breach affecting 7,864 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
FLInvestigation

Robinhood Crypto, LLC.(Robinhood)

Florida Attorney General James Uthmeier launched an investigation into Robinhood Crypto, LLC for allegedly deceptive practices regarding trading costs. The AG issued a subpoena seeking internal documents to determine if Robinhood violated Florida's Deceptive and Unfair Practices Act by falsely claiming to offer the lowest crypto trading costs. Robinhood must respond by July 31, 2025.

Low
HHSEnforcement Action

Mountain Laurel Dermatology

Mountain Laurel Dermatology (Healthcare Provider, NC) reported a HIPAA breach affecting 3,324 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
MASettlement

Earnest Operations LLC(Earnest)

Massachusetts Attorney General settled with Earnest Operations LLC for $2.5 million over allegations that the student loan lender's use of AI underwriting models led to disparate impact on Black, Hispanic, and non-citizen applicants. The company failed to test its AI models for bias, used discriminatory variables like Cohort Default Rate, and sent inaccurate adverse action notices. Earnest must pay the fine, discontinue problematic practices, and implement compliance measures.

HighAI/Automated DecisionsNotice Failure

$2.5M

HHSEnforcement Action

Naper Grove Vision Care

Naper Grove Vision Care (Healthcare Provider, IL) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure
HHSEnforcement Action

Florida Lung, Asthma & Sleep Specialists (FLASS)

Florida Lung, Asthma & Sleep Specialists (FLASS) (Healthcare Provider, FL) reported a HIPAA breach affecting 10,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

MediumData BreachHealth DataSecurity Failure
HHSEnforcement Action

Ascension Health Services LLC dba Alpha Wellness & Alpha Medical Centre

Ascension Health Services LLC dba Alpha Wellness & Alpha Medical Centre (Healthcare Provider, GA) reported a HIPAA breach affecting 1,714 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.

LowData BreachHealth DataSecurity Failure

Explore Enforcement Data